bug#66304: exim vulnearable to CVE-2023-42115 et al

2023-10-06 Thread John Kehayias via Bug reports for GNU Guix
Hello, On Thu, Oct 05, 2023 at 05:25 PM, Wilko Meyer wrote: > * gnu/packages/mail.scm (exim): Update to 4.96.1. > --- > gnu/packages/mail.scm | 5 +++-- > 1 file changed, 3 insertions(+), 2 deletions(-) > > diff --git a/gnu/packages/mail.scm b/gnu/packages/mail.scm > index 72d971eb77..e69236

bug#66304: exim vulnearable to CVE-2023-42115 et al

2023-10-02 Thread Wilko Meyer
Hi Guix, Exim currently has unpatched vulnearabilities regarding its EXTERNAL Auth driver as well as its SPA/NTLM authenticator. According to the project[0] prospective fixes seem to be around the corner. We should probably bump the Exim version we ship to a non-vulnearable version as soon as o